Missing Encryption of Sensitive Data in Brocade SANnav - CVE-2022-28167
Published: June 24, 2022 / Updated: June 24, 2022
Vulnerability identifier: #VU64655
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-28167
CWE-ID: CWE-311
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to Brocade SANanv logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log. A local user with access to log files can view passwords of other users in plain text.
Affected software
Brocade SANnav
HPE SANnav Management Software
Connectrix (Brocade)
HPE SANnav Management Software
Connectrix (Brocade)
How to mitigate CVE-2022-28167
Install updates from vendor's website.
Brocade SANnav - addressed in versions 2.1.1.8, 2.2.0.2
HPE SANnav Management Software - addressed in versions 2.1.1.8, 2.2.0.2
Connectrix (Brocade) - addressed in versions 2.1.1.8, 2.2.0.2
HPE SANnav Management Software - addressed in versions 2.1.1.8, 2.2.0.2
Connectrix (Brocade) - addressed in versions 2.1.1.8, 2.2.0.2